HomeSecurityHow GlassWorm returned to developers' code

How GlassWorm returned to developers' code

The widespread and versatile malware that was thought to have been eradicated has returned to development environments. Just two weeks after the open source project OpenVSX that GlassWorm had been “fully contained and shut down,” the self-replicating worm is once again targeting Visual Studio Code, add-ons that enhance the open source VS Code, providing new features, debuggers, and other tools to improve developers’ workflows.

See also: Open VSX: Addresses Token Leaks and Malicious Extensions

GlassWorm

Researchers from Koi have discovered a new wave of infections and three more compromised extensions. GlassWorm, first discovered in October, uses non-displayable Unicode characters to make malicious code invisible to code editors in VS Code environments. The worm has also infiltrated GitHub repositories, hiding payloads in AI-generated commits that appear to be legitimate code changes.

It was released by a Russian-based attack group and is infecting victims around the world. These include dozens of individual developers and businesses in the US, Europe, Asia, South America, and “a major government entity” in the Middle East. “The same attacker infrastructure is still fully operational,” the Koi researchers note. They add, “this is no longer just about compromised extensions. This is about real victims, critical infrastructure at risk, and a worm that is doing exactly what we warned it would do: It spreads through the developer ecosystem.”.

It also compromises GitHub repositories. Koi researchers discovered three new OpenVSX code extensions that contain GlassWorm and have been downloaded at least 10,000 times in total: adhamu.history-in-sublime-merge (downloaded 4,000 times) ai-driven-dev.ai-driven-dev (downloaded 3,300 times) yasuyuky.transient-emacs (downloaded 2,400 times). All three GlassWorm extensions are “still literally invisible” to code editors, the researchers note. They are encoded in non-printable Unicode characters that look like white space to the human eye, but execute as JavaScript.

See also: Self-replicating worm detected in Visual Studio Code

How GlassWorm returned to developers' code
How GlassWorm returned to developers' code

The attackers have published new transactions on the Solana blockchain that describe updated remote control and control points (C2) for distributing malicious payloads. But while these transactions are fresh, the servers remain unchanged, the researchers note. Developers also report that their GitHub repositories have been compromised with commits that appear to be “project-specific” code changes generated by AI as part of normal development activity. These commits include the same invisible Unicode malware as those in VS Code. In addition, the attackers are stealing GitHub credentials and using worming techniques to push commits to additional repositories.

Developers and security teams should focus on critical signals: malicious extensions containing invisible Unicode characters that are being uploaded, hidden C2 channels that use blockchain notes and legitimate services like Google Calendar to evade takedowns, and infected developer machines used as proxy nodes to launch further infections.

Companies should reduce attack surfaces by only allowing components from trusted publishers, disabling automatic updates where possible, and maintaining an inventory of installed extensions, as well as monitoring for anomalous outbound connections from workstations, credential harvesting activity for developer-level tokens (npm, GitHub, VS Code), and proxy or VNC creation.

See also: Hackers abuse VS Code extensions to develop Ransomware

How GlassWorm returned to developers' code
How GlassWorm returned to developers' code

Additionally, security teams should apply the “same rigor” they use for third-party libraries to their own developer toolkits. “When malicious actors treat your IDE [integrated development environment] as a launchpad, your supply chain exposure expands dramatically.”

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS